Undisclosed telemetry endpoints, cross-service token sharing, and WebRTC SDP exposure — documented from packet captures, labeled by evidence state.
We use OpenAI. We are a paying ChatGPT Business customer, and we value parts of the platform enough to build on it. We audit it anyway — because that is the relationship we want with every supplier, including ourselves. Nothing on this page is an anti-OpenAI campaign; it is the same scrutiny we would apply to our own stack.
HAR captures across multiple sessions show 47 telemetry requests per session to endpoints that do not appear in OpenAI's public documentation. The collection volume and request composition did not measurably change when the training opt-out toggle was set.
SAPISIDHASH authentication tokens were transmitted in contexts shared with Google services, and WebRTC SDP data exposing local network topology was present in session traffic.
The opt-out toggle, as implemented in the settings surface we tested, does not appear to gate the telemetry collection we captured. The data path exists independently of that control.
We think a consent control that does not gate the collection a user would reasonably associate with it is inadequate, whatever the legal fine print says.
If OpenAI or any third party can show these captures are misread, we will publish the correction.
Full HAR captures, endpoint documentation, and reproduction steps are being finalized for open publication. Personal identifiers are redacted; hashes and timestamps retained for provenance.
We do not silently rewrite findings. If a claim changes, the change stays visible.